Live data from Hacker News

"Localhost tracking" explained. It could cost Meta €32B

zeropartydata.es

201–210 of 286 posts

Re: "Localhost tracking" explained. It could cost Meta €32B

#201
post #193

Earlier quoted context omitted.

I can understand it of course. But in this case I feel personally offended. I would like to see the money handed to me.

If most people in your country use Meta apps, whether it's a tax discount spread across the population or a payout spread across the userbase doesn't make a difference. Personally I would like to see some execs go to prison, rather than taxing/fining a monopolistic corporation, which achieves nothing.

You don't have to explain taxes to me, it is a concept that is pretty easy to grasp, and - even though I understood it already - the grandparent post also explained it . And I touched the subject in my original post.

I guess what I am looking for is some kind of personal apology. And that could be manifested in a refund to mu bank account. As I explained above.

I don't think sending people to prison helps much.

A personal check would open the eyes for a lot of people and make them realize that this company committed a crime. Against you. And you are worth it.

Re: "Localhost tracking" explained. It could cost Meta €32B

#202

"The Meta Pixel script sends the _fbp cookie to the native Instagram or Facebook app via WebRTC (STUN) SDP Munging." Crazy to deploy a hack like this at the scale of Meta.

yeah...how does this get approved?

"approved?" In a company where ads are the lifeblood and where the targeting specificity of ads determines their value, whichever engineers put this together are guaranteed to have gotten fantastic promo packets.

Re: "Localhost tracking" explained. It could cost Meta €32B

#203

Earlier quoted context omitted.

I like the idea, but I see no reason to shield the management that demanded this of the rank and file. Accountability should go all the way up the chain.

Yes, but it should include everyone involved, from top to bottom. We won't get those data theft misfeatures if engineers refused to work on them out of personal liability.

I once bluntly refused to deploy an app to production because it was a finance system that handled billions of dollars and the personal data of a million children. The HTTPS certificates couldn’t be organised on time (don’t ask), so I simply refused to deploy it using HTTP only “just for now” (=years).

The look of stunned shock on the project manager’s face is something I’ll never forget.

He was apoplectic with mixed rage and incredulity.

“How dare you refuse a direct order!?” — but now picture a red face and spittle literally flying around the room.

He immediately called my supervisor and up all the way to the CEO of my consultancy.

That’s what happens when individual contributors push back. In general there are zero legal, corporate, or personal protections.

“Do as I say or consequences.” is the norm.

In this situation I was incredibly lucky that the CEO trusted my judgement and told the PM to take a hike. Even if I had been fired I would have been okay.

Most people can’t take risks like that on principle.

That’s fundamentally why enshittification happens, and why every mobile apps’ data collection dragnet would make an NSA spook blush.

Only consequences for directors and up matter. They're the ones that need to feel the fear, not the poor outsourcer struggling to put food on his family table.

Re: "Localhost tracking" explained. It could cost Meta €32B

#204
post #186

This system was designed and implemented by engineers who committed code in a source control system with their name attached, and the changes were requested by product managers in tickets in the ticketing system with their name attached. Those engineers and product managers should be personally liable for an equivalent % of their annual salary as Facebook is liable for a % of its annual revenue.

Sounds like the modern version of the CS Lewis quote: > The greatest evil is not now done in those sordid dens of crime that Dickens loved to paint. It is not done even in concentration camps and labour camps. In those we see its final result. But it is conceived and ordered (moved, seconded, carried, and minuted) in clean, carpeted, warmed and well-lighted offices, by quiet men with white collars and cut fingernails…

Too true. See also the movie Conspiracy.

Re: "Localhost tracking" explained. It could cost Meta €32B

#205
post #92

Remember in 2014 when the Android Twitter app started sending a list of all your installed applications back to Twitter? https://news.bloomberglaw.com/privacy-and-data-security/twit... Ever since then I refused to install native versions of apps that could be used in a browser. I don't use Facebook or Instagram so I don't know if that works anymore, and I recall testing that they were intentionally crippling Facebook…

this is still perfectly legal and allowed. every app can scan your apps and recently opened ones "for security". same for your contacts. whatsapp (only meta product i need to touch in our fleet) will do both at very fast intervals, and upload a contact list diff if it detect changes. the whole issue here was that meta bypassed the user matching on the web without paying google "cookie matching" price

"Legal" is missing the point by a mile and is irrelevant.

Re: "Localhost tracking" explained. It could cost Meta €32B

#206

"The Meta Pixel script sends the _fbp cookie to the native Instagram or Facebook app via WebRTC (STUN) SDP Munging." Crazy to deploy a hack like this at the scale of Meta.

Shouldn't a sensible CORS policy by the webserver block these access attempts?

Of course the website owner wants the tracking, but I think they should also be a guilty party here next to Facebook, even if they just bought the service.

Re: "Localhost tracking" explained. It could cost Meta €32B

#207

Earlier quoted context omitted.

Yes, but it should include everyone involved, from top to bottom. We won't get those data theft misfeatures if engineers refused to work on them out of personal liability.

I once bluntly refused to deploy an app to production because it was a finance system that handled billions of dollars and the personal data of a million children. The HTTPS certificates couldn’t be organised on time (don’t ask), so I simply refused to deploy it using HTTP only “just for now” (=years). The look of stunned shock on the project manager’s face is something I’ll never forget. He was apoplectic with mixed…

> Most people can’t take risks like that on principle.

I actually think many people could, and the more who do, the easier it gets

Re: "Localhost tracking" explained. It could cost Meta €32B

#208
post #110

Earlier quoted context omitted.

I'd agree at a personal/moral level there is equal responsibility. However that doesn't recognise both the power and risk/reward imbalance here. If you, as an employee did this - maybe you'd add a few dollars to your stock options over time. If your Zuck - that's potentially billions. And in terms of downside - if you are Zuck and stop it in the company - there is no comeback - if you are an engineer blowing the whis…

Sounds like a typical blurring of responsibility through bureaucracy. "If Zak is a billionaire, then he is responsible, but since he essentially did nothing wrong, then no one will be held accountable." Total nonsense. There are specific crimes, and there are specific people who planned this crimes, specific peoples who ordered them to be carried out, and who carried them out. And these people should be held accounta…

It's complex - that's why you have judges and juries - to make judgements.

I'm saying leaders bear more responsibility than foot soldiers - I'm not saying foot soldiers don't also have a responsibility - but 'I didn't physically do it' isn't a defence for those that gave the orders/ created a culture where it happened.

Sure, Zuck might not really known and that is a mitigation. But I think the interesting question here is what does everybody ( in the commpany ) think would have happened if he did find out? Would it have been a 'well done, that's clever/cool nod and a wink', or would they expected to have lost their jobs?

It's easy to frame laws to make it the leaders responsibility - it's their job to know - their job to act if they find out - their job to put systems and procedures in place to ensure illegal activity isn't happening on their watch.

And back to the billionaires/foot soldiers thing. Motive also matters - if people did it because of fear of losing their jobs that's a mitigating factor - if people materially benefited to the tune of millions - that's another factor. If you steal - the punishment scales with the value of the theft - same principal - if you want the law to be a deterrent then the punishment has to fit the crime. A fine of 1 million isn't going to stop Zuck doing it again is it?

Re: "Localhost tracking" explained. It could cost Meta €32B

#209
post #185

Earlier quoted context omitted.

> if your employees, without your knowledge, somehow decided that the only way they could reach their targets was to commit a crime, why should you be held responsible for that? Thats where "known or should have known " becomes relevant. It's your company, it's your responsiblity to know what they are doing.

No, what you are suggesting is a typical strategy of avoiding punishment and creating an opportunity to break the law. A very common strategy, used everywhere, especially in dictatorial and socialist regimes. There is a substitution of one real crime, committed by real people, for a crime "they didn’t know, but should have" against other people, for which there is no real responsibility, while the real criminals are…

So your argument is that because the ring leaders, and the people who benefit the most from the crimes, almost always get off - we should forget about them and just penalize the people who have to do what they are told because they need to feed their families?

That would seem to be a recipe for more crime, not less.

Note i don't think anyone is saying those directly involved should get off scot-free, just that those really responsible shouldn't.

Re: "Localhost tracking" explained. It could cost Meta €32B

#210

The same European intellegentsia that is progressively forcing Apple to tear down the walled garden simultaneously fails to understand that this is exactly why they had it in the first place: > You’re not affected if (and only if) . . . > You browse on desktop computers or use iOS (iPhones) At the very least they should step back and allow companies to enforce safeguards because they clearly lack the understanding or…

Is there anything in those EU directives that requires browsers to let webpages connect to localhost? Because that's the main issue here. And also maybe apps should need permission to listen on ports or connect to localhost, but I doubt the regulation prevents that either.

On https://localmess.github.io/, they think that this is technically possible on iOS too, and the main reason it wasn't done there is due to restrictions on apps running in the background.

This is nothing new that has been opened up because of those regulations.

Post reply on HN